Cloud Access Service Updates
The following subsections outline the new and enhanced features of the Cloud Access Service (CAS).
Simplified Authenticator Registration and Authentication with QR Codes
Users can now register and authenticate with the RSA Authenticator app directly from the same iOS or Android device. QR codes displayed in My Page > Authenticators and web authentication screens are now tappable, allowing registration or authentication details to be transferred directly to the RSA Authenticator app with a single tap. This eliminates the need to manually copy registration details or switch between apps multiple times, providing a faster and more seamless experience.
Identity Verification Enhancements for Secure Authentication
Authenticating with Identity Verification is now available as an authentication option in Access Policies. You can use Identity Verification as a primary or step-up authentication method to provide users with an additional way to verify their identity during sign-in. This feature helps you maintain secure access, supports users who cannot complete self-service authentication, enables secure emergency access to web-based resources, and provides a higher-assurance verification option.
Additionally, Identity Verification now supports encrypted Login Hint JWTs to help protect authentication data. To enable this enhancement, select the Login Hint JWT encrypted option in the ID Dataweb Administration Console, generate a public key, and add it to the new Encryption Public Key field in the Identity Verification Provider configuration in the Cloud Administration Console. To enable this feature, contact RSA Customer Support.
Hybrid Domain Join Support for Microsoft Office 365 Direct STS
You can now use CAS as the identity provider (IdP) for Microsoft Office 365 Direct STS to enable hybrid Microsoft Entra join for devices that are already joined to Active Directory. When you enable the Hybrid Join Devices setting, you can configure applications for hybrid Microsoft Entra joined devices. Optionally, you can upload a trusted certificate from the Connection Profile tab. A trusted certificate is required only when users sign in to Windows devices using the MFA Agent. This enhancement helps users securely access resources and simplifies device management.
Note: Identity Router (IDR) version 12.26.0.0 is required to use this capability.
REST Agent Configuration Enhancements
REST Agent configuration now supports PEM certificates in addition to the existing DER format, providing better compatibility with different integrations. Certificate upload validation has been improved to ensure that uploaded certificates are currently valid, unexpired, self-signed Root CA certificates with certificate-signing capability. PEM certificates are supported in IDR version 12.26.x. IDR versions earlier than 12.26.x support only DER certificates.
Action Required: Update to Company-Specific URLs Before August 25, 2026
Support for non-company-specific URLs will be permanently shut down on August 25, 2026. You must update all affected service URLs to use your designated company-specific URLs before this date. For more information, see Company-Specific Administrative URLs Update Instructions and Final Notice: Permanent Shutdown of Non-Company-Specific URLs. You must use your designated company-specific URLs for all access, including API interactions, Authentication Manager (AM) configurations, SCIM configurations, and redirected URLs from identity providers (IdPs). Access through non-company specific URLs is not yet blocked; however, when it is blocked on August 25, it will result in loss of functionality (for example, https://access.securid.com or https://na2.access.securid.com). To ensure uninterrupted access, you should promptly verify that all connectivity is routed through the appropriate company-specific URLs and update their configurations as needed. If your Identity Router (IDR) software version is earlier than 12.22.0.0.32, you must delete and reinstall Identity Router software using a newly downloaded IDR image (upgrade is not supported for v12.22 and earlier) to avoid any disruptions when non-company-specific URLs are permanently shut down.
Starting with the June 2025 release, a banner warning appears for 24 hours whenever a non-company-specific URL is used for the following:
- Logging in to the Cloud Administration Console via password or third-party IdP.
- Accessing the Cloud Administration REST APIs.
In addition, an audit event is logged once per day whenever a non-company-specific URL is used for third-party IdP login and Cloud Administration REST API. You can view this event from the Cloud Administration Console by navigating to Platform > Admin Event Viewer.
As part of the effort to permanently shut down non-company-specific URLs, the Software and Adapter Repository URLs used by IDRs will be updated to company-specific URLs starting with the June release. As a result, customers are advised to review their network configurations and ensure that the new URLs are whitelisted, if applicable.
Old URL format:
- Software Repo: https://public-apprepo-<tenantName>.<accessRegion>.securid.com
- Adapter Repo: https://public-connectorrepo-<tenantName>.<accessRegion>.securid.com
New URL format (Whitelisted):
- Software Repo: https://companyName.{baseAccessDNSName}.securid.com
- Adapter Repo: https://companyName.{baseAccessDNSName}.securid.com
GOV Deployment
Old URL format:
- Software Repo: https://public-apprepo-<tenantName>.<accessRegion>.securidgov.com
- Adapter Repo: https://public-connectorrepo-<tenantName>.<accessRegion>.securidgov.com
New URL format (Whitelisted):
- Software Repo: https://companyName.{baseAccessDNSName}.securidgov.com
- Adapter Repo: https://companyName.{baseAccessDNSName}.securidgov.com
A Status Monitor is already available to validate connectivity. If the status is healthy, no action will be required after the change.
You can verify this from the Cloud Administration Console by navigating to Platform > Identity Router and expanding the Identity Router section to view the status indicators. For more information, refer to this IDR Advisory.
Identity Router (IDR) 12.26.X Now Available
The IDR 12.26.x release is now available. RSA recommends that all customers upgrade to this version.
Identity Router Update Schedule
Identity routers are updated according to the following schedule. Download the latest identity router image when you deploy new identity routers to benefit from the latest security improvements.
| Date | Description |
|---|---|
|
ANZ: August 24, 2026 |
Updated IDR software is available to all customers.
|
|
Default: October 10, 2026 |
Default date when IDRs are scheduled to automatically update to the new version unless you modify the update schedule or update manually.
|
|
Last Permitted: November 11, 2026 |
If you have postponed the default date, this is the final day on which updates can be performed.
|
|
Enforced: November 14, 2026 |
If the IDR is not upgraded after the last permitted date for any reason, RSA automatically initiates a mandatory upgrade seven days later. You will receive an email notification and a Cloud Administration Dashboard alert with the scheduled update date.
|
Upcoming End of Primary Support (EOPS) Details
The following table provides details on RSA products reaching the end of support within the next six months.
| Product | Version | EOPS Date | Extended Support Level 1/Level 2 |
|---|---|---|---|
| Authenticator for iOS & Android | 4.5 | October 2026 | |
| MFA Agent for Microsoft Windows | 2.3.3/2.3.4/2.3.5 | December 2026 | |
| RSA Authentication Manager | 8.7 SP2 | January 2027 | January 2028 / January 2029 |
For more details, refer to Product Lifecycle.
Product Documentation and Support
Visit RSA Community to access the latest version of the product documentation, answers to common questions, solutions to known problems, community discussions, and case management.
Subscribe to status.securid.com for the Cloud Access Service Status Updates
For information about all service incidents and scheduled maintenance windows for the Cloud Access Service, subscribe to https://status.securid.com.
Related Articles
RSA July 2026 Release Announcements 30Number of Views RSA June 2026 Release Announcements 46Number of Views RSA February 2026 Release Announcements 45Number of Views RSA March 2026 Release Announcements 34Number of Views RSA August 2023 Release Announcements 56Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Governance & Lifecycle 8.0.0 Installation Guide How to Download OTP Token Seed Files from myRSA How to Detect and Resolve Stalled Workflows and Workpoint Issues in RSA Identity Governance & Lifecycle RSA Identity Governance & Lifecycle - Access Certification whitepaper